CAPTAIN Protocol Adapter for Tactical Network Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current In-Line Network Encryptor (INE) devices impair the operation of networking protocols and network optimization techniques, particularly in tactical networks with dynamically varying link characteristics and asymmetric links, and preclude operations like multicast and disruption tolerant networking, while also rendering cybersecurity less effective due to limitations in deep packet inspection.
Innovation Solution
The Crypto-Partitioning Aware Protocol adapter for Tactical Networks (CAPTAIN) intercepts data packets, identifies unencrypted fields, and populates them with messages that can be read by other protocol adapters, enabling the implementation of performance-enhancing proxy functions across INEs, such as HAIPE devices, to facilitate unimpeded protocol operations and security protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data packets are encrypted by INE devices to protect sensitive content in untrusted networks, then security against eavesdropping is improved, but protocol operation and network optimization techniques are impaired
Solution Approach 1:
The patent segments the data packet into different parts: encrypted payload content and unencrypted pass-through fields. This segmentation allows the encrypted portion to provide security while the unencrypted portion enables protocol operations and network optimization techniques to function across the INE device.
Solution Approach 2:
The patent introduces protocol adapters as intermediary devices that populate pass-through fields with appropriate information before encryption and interpret these fields after decryption. These adapters enable protocol operations to work across the encrypted link without compromising security.
2Reliability
If deep packet inspection is blocked by encryption to maintain security, then security is improved, but cybersecurity effectiveness is reduced
Solution Approach 1:
The patent segments the packet into encrypted content and unencrypted pass-through fields, allowing security mechanisms to inspect the unencrypted fields for threats while the encrypted content remains protected. This enables cybersecurity effectiveness without compromising security.
Solution Approach 2:
Protocol adapters act as intermediaries that populate pass-through fields with information that can be inspected by security systems. This allows deep packet inspection to function on the unencrypted fields while the main content remains encrypted and secure.
3Reliability
If all data fields are encrypted to ensure security, then security is improved, but network optimization and protocol functions cannot operate
Solution Approach 1:
The patent divides the data packet into encrypted and unencrypted segments, with pass-through fields remaining unencrypted to enable network optimization functions while the main content stays encrypted for security.
Solution Approach 2:
The patent applies different encryption qualities to different parts of the packet: full encryption for sensitive content and no encryption for pass-through fields that need to be processed by network optimization functions and protocol adapters.
Data Source
AI summary
This disclosure is directed to techniques for providing communication between devices in different networks wherein the communication must first pass through an encryption mechanism and the devices do not have the stand-alone capability to encrypt or decrypt the communication. According to these techniques, an adapter may determine certain fields in a data packet that remain unencrypted when the data packet passes through the encryption mechanism. The adapter may then process those fields in such a way that, when the data packets are received by a second adapter, the second adapter may read those fields and obtain information.


